CVE-2024-4622: alpitronic Hypercharger EV Charger Use of Default Credentials
If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the device is using default credentials, change the administrator credentials so the web interface cannot be accessed using public default credentials.
alpitronic Hypercharger EV charging device web interface administrator credentials (change default credentials) = Change the default administrator username/password
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4622?
CVE-2024-4622 is considered a high-severity vulnerability due to the potential for unauthorized administrative access.
How do I fix CVE-2024-4622?
To fix CVE-2024-4622, ensure that default credentials on the alpitronic Hypercharger EV charging device are changed to strong, unique passwords.
What are the risks associated with CVE-2024-4622?
The risks associated with CVE-2024-4622 include unauthorized access to the device, potential manipulation of settings, and compromise of network security.
Which devices are affected by CVE-2024-4622?
CVE-2024-4622 affects alpitronic Hypercharger EV charging devices that are misconfigured and retain default credentials.
Is there a known exploit for CVE-2024-4622?
While there may not be a specific known exploit, the vulnerability allows attackers to use default credentials to gain unauthorized access.